acme.sh - sponsored and maintained by ZeroSSL since 2021

You landed here because acme.sh never had a dedicated website, this is its new home. If you need to access the Github repository, click on one of the links below.

The certificate lifecycle is speeding up - acme.sh keeps you ahead of it.

With certificate lifetimes shrinking to 47 days, manual renewal isn't an option anymore. acme.sh, sponsored and maintained by ZeroSSL, is the automation layer built for that reality β€” from flexible DNS validation to renewal timing the certificate authority itself controls.

It's free. No credit card required.

Why do we sponsor acme.sh?

ZeroSSL is the default certificate authority for acme.sh, making it one of the most widely used integrations for automated SSL certificate management. By sponsoring the project, ZeroSSL ensures long-term reliability, compatibility, and continuous improvement for the global ACME ecosystem. This partnership provides users with a seamless experience, from issuing certificates to maintaining them at scale.

Certificate validity periods are shrinking

With certificate lifetimes on track to hit 47 days, manual renewal isn't sustainable anymore. acme.sh, sponsored and maintained by ZeroSSL, is a lightweight, fully automated ACME client built for exactly this shift β€” pure shell script, no dependencies, and no root access required.

acme.sh handles the entire certificate lifecycle end-to-end, from issuance to renewal, and gives you the flexibility to adapt as validation and CA requirements evolve.

  • ARI (ACME Renewal Information) support, the CA tells the client the ideal renewal time, not the other way around
  • Cron-based automated renewals, checked every 6 hours
  • Account key rollover without re-registering or new credentials
  • Built to handle renewal cycles as short as 47 days.
Certificate validity periods are shrinking

Simplified Certificate Management

acme.sh is a lightweight, fully automated ACME client that allows you to issue, install, and renew SSL/TLS certificates with minimal setup. Built as a pure shell script, it integrates seamlessly into existing workflows and infrastructure without adding complexity.

With native support for ZeroSSL, acme.sh enables developers and system administrators to automate certificate management end-to-end, from verification to deployment. Designed for simplicity and flexibility, acme.sh provides everything needed to manage SSL certificates at scale. It works across environments, supports multiple validation methods, and automates the entire certificate lifecycle.

  • Automatic SSL/TLS certificate issuance and installation
  • Flexible DNS validation - alias mode, account-based challenges for 180+ DNS providers, plus standard HTTP validation
  • Wildcard + multi-domain support via DNS-01
  • Zero dependencies - pure POSIX shell, runs on Linux, macOS, BSD, and containers
Simplified Certificate Management

Buying SSL certs standalone is a thing from the past.

We're not in 2016 anymore, ZeroSSL pioneered Certificate as a Service in its inception year 2020. One subscription. Every cert you'll ever need.

βœ“ Native ZeroSSL integration out of the box
βœ“ Works with any ACME-compliant CA - never locked in
βœ“ Improved compatibility across servers and environments
βœ“ Long-term investment in automation and security standards

Γ— Buy a single cert, repeat multiple times per year
Γ— Overpay for multi-year SSL deals
Γ— Per-domain pricing that doesn't scale
Γ— Vendor lock-in with opaque pricing

Buying SSL certs standalone is a thing from the past.
Trusted by Security Leaders

acme.sh is well known and used by the biggest companies in the PKI space. Keyfactor CLM, Amazon Certificate Manager (ACM) and Sectigo Certificate Manager (SCM) Pro to name a few.

Key Features

Four qualities explain why acme.sh has become the default choice for certificate automation.

Flexible DNS Validation

acme.sh supports DNS alias mode, letting you delegate the challenge to a separate domain (e.g. a fresh Cloudflare account) so you never touch your legacy registrar's API directly. It also supports the newer account-based DNS challenge, which lets validation persist across renewals without repeating DNS changes every time.

Built for 47-Day Certificates

Support for ARI (ACME Renewal Information) means the certificate authority tells the client the ideal renewal window instead of guessing β€” backed by 6-hour cron checks for hands-off automation.

Secure Key Management

Account key rollover lets you rotate your ACME account's signing key without creating a new account or new credentials, keeping your certificates and ZeroSSL binding fully intact.

Wildcard & Multi-Domain Support

Full wildcard and multi-domain issuance via the DNS-01 challenge method.

How does acme.sh compare?

Those features are only half the story β€” how they hold up against the most common alternative matters just as much. Certbot remains the default entry point for many teams, and for good reason: it was built by the same team that created the ACME protocol and Let's Encrypt itself, back in 2015, and has been the default recommendation ever since.
That head start explains its popularity, but for anything beyond the basics, the differences add up quickly.

How does acme.sh compare?

Those features are only half the story β€” how they hold up against the most common alternative matters just as much. Certbot remains the default entry point for many teams, and for good reason: it was built by the same team that created the ACME protocol and Let's Encrypt itself, back in 2015, and has been the default recommendation ever since. That head start explains its popularity, but for anything beyond the basics, the differences add up quickly.

Feature acme.sh Certbot Certbot
Zero dependencies Pure shell script, meaning it runs anywhere: routers, containers, minimal Linux distributions. Certbot's full Python runtime.
No root required Install and run acme.sh as any user. Certbot typically needs elevated privileges.
TLS-ALPN-01 support acme.sh supports validation over port 443, useful when port 80 is blocked or DNS API access isn't available. Not supported.
Broader DNS automation Native support for 180+ DNS providers for hands-off wildcard and multi-domain issuance. 40+ DNS providers.
CA flexibility Works with any ACME-compliant certificate authority, so you're never locked into one provider. Same.
CA independence & resilience acme.sh is CA-agnostic by design. Run ZeroSSL as your primary, a second CA as a hot fallback, and a regional CA for compliance β€” all from the same tool, no forking, no emergency scramble. CA-agnostic by configuration.
Zero dependencies
acme.sh
Pure shell script, meaning it runs anywhere: routers, containers, minimal Linux distributions.
CertbotCertbot
Full Python runtime.
No root required
acme.sh
Install and run as any user.
CertbotCertbot
Typically needs elevated privileges.
TLS-ALPN-01 support
acme.sh
Supports validation over port 443, useful when port 80 is blocked or DNS API access isn't available.
CertbotCertbot
Not supported.
Broader DNS automation
acme.sh
180+ DNS providers.
CertbotCertbot
40+ DNS providers.
CA flexibility
acme.sh
Works with any ACME-compliant CA.
CertbotCertbot
Same.
CA independence & resilience
acme.sh
CA-agnostic by design β€” run multiple CAs from the same tool, no forking, no emergency scramble.
CertbotCertbot
CA-agnostic by configuration.
FAQ

Frequently Asked Questions

Common questions about ZeroSSL & acme.sh we often get.

SSL/TLS certificates are now short-lived by design, requiring frequent renewal to maintain security. Automation ensures your certificates are always valid, preventing outages and ensuring continuous HTTPS protection across all your domains.

Missed renewals lead to expired certificates, browser warnings, and lost user trust. With ZeroSSL ACME automation, certificates are issued and renewed automatically in the background, eliminating manual errors and downtime risk.

The ACME protocol connects your infrastructure directly to ZeroSSL, enabling automated domain validation, certificate issuance, and renewal without manual interaction. This allows you to scale SSL management effortlessly across projects and environments.

ZeroSSL offers free ACME-based 90-day certificates, ideal for most standard use cases.
For advanced needs such as higher issuance volumes, extended certificates, or business-critical infrastructure, ZeroSSL paid plans provide additional flexibility, limits, and support.

ZeroSSL is deeply integrated with acme.sh and other ACME clients, offering:

βœ“ Free, automated certificate issuance

βœ“ Broad compatibility across environments

βœ“ A clear upgrade path to scalable paid plans

This makes ZeroSSL suitable for both individual developers and enterprise deployments.

As infrastructure grows across servers, containers, and dynamic domains, manual SSL management becomes impractical. With acme.sh and ZeroSSL, you can centrally automate certificate lifecycle management while upgrading to paid plans when higher scale, performance, or support is required.

Certificate lifetimes have been shrinking fast β€” from 398 days, to 200, to 90, heading toward 47. If your infrastructure isn't automated yet, you're already behind, not preparing for the future. ZeroSSL has built and funded acme.sh for six years for exactly this moment β€” free to use, and paired with our own certificates starting at just $9.99/month, so individuals, small teams, and enterprises alike have no excuse left to wait.

Questions answered? Here's how to get started with ZeroSSL & acme.sh.

Start automating with ZeroSSL

Get ready to automate your SSL certificate needs.

ZeroSSL offers fast issuance, ACME‑first workflows, and globally trusted certificate management. Combine our expertise in PKI with the most well known and public trusted ACME client.

Get started with ZeroSSL

#1 trusted ACME client

acme.sh is the most widely used ACME client, trusted by developers and infrastructure teams worldwide. With 40k+ GitHub stars and broad real-world adoption, it has become the go-to solution for automated SSL/TLS certificate management.

View on Github